We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
5,208 Software Downloads


RawCap is a tiny (17KB) command line packet sniffer for Windows that uses raw sockets.

The program is straightforward to use. Just launch it, choose your network interface from a list, enter an output file name if you like, and that's it: RawCap will capture all network traffic. Press Ctrl+Break when you're finished to make it stop.

Or, if you'd rather not use RawCap's interactive mode, you can provide your interface IP address and output file name at the command line, something like RawCap.exe dumpfile.pcap

While there are plenty of packet sniffers around, RawCap wins out over many due to its sheer simplicity. It's small, needs no external support beyond .NET 2.0, makes minimal demands on RAM and your CPU, and yet works with most interface types (including wifi and PPP).

You do need administrative privileges to run RawCap, though. And as the authors note, raw socket sniffing in Windows Vista or higher can be unreliable: "you might not receive either incoming packets (Win7/8) or outgoing packets (Vista)" (XP works fine). Still, it's free, and easy to use - just download the program and see if it works for you.

Platforms: Windows 7 (32 bit), Windows 7 (64 bit), Windows Vista (32 bit), Windows Vista (64 bit), Windows XP
Licence: Freeware
Manufacturer: NETRESEC
Date Added: {ts '2013-12-29 11:21:00'}

IDG UK Sites

Best camera phone of 2015: iPhone 6 Plus vs LG G4 vs Galaxy S6 vs One M9 vs Nexus 6

IDG UK Sites

In defence of BlackBerrys

IDG UK Sites

Why we should reserve judgement on Apple ditching Helvetica in OS X/iOS for the Apple Watch's San...

IDG UK Sites

Retina 3.3GHz iMac 27in preview: Apple cuts £400 of price of Retina iMac with new model